Back to Vulnerability Directory
HIGHFixed upstream

CVE-2024-52979

Elasticsearch: crafted search templates with Mustache functions crash the node

Technology

Elasticsearch

CVSS Score

7.5 / 10.0

Affected Versions

Before 7.17.25; before 8.16.0

Upstream Fix

7.17.25; 8.16.0

Published

May 1, 2025

OSSeva Coverage

Fixed upstream

Description

Uncontrolled resource consumption while evaluating specially crafted search templates with Mustache functions can crash an Elasticsearch node, causing a denial of service. Fixed in 7.17.25 and 8.16.0. NVD scores the record 7.5; Elastic scores it 6.5.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running Before 7.17.25; before 8.16.0, you need this patch. Book a discovery call to get covered.